New reporting from Bloomberg reveals how U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a widespread campaign by Beijing to steal customer data.
The hacks were carried out by a group known as Salt Typhoon, compromising hundreds of companies including AT&T, Verizon, Viasat, Charter and Windstream. The goal was to collect phone records and information about senior U.S. government officials.
T-Mobile’s cybersecurity staff spent months searching for the hackers without success before identifying unusual behavior on one system connected to a different telecom company's router. Jeff Simon, T-Mobile’s cybersecurity chief, drove to the data center nearby with colleagues, found the compromised system, and physically cut the cable connecting it to the outside world.
This incident highlights the growing threat of state-sponsored hacking and how tech giants must remain vigilant in protecting sensitive information. It also underscores the innovative methods required to counteract such threats.







